7 ms·
After a host made a suspicious/creepy comment about our stay, I started logging into host routers (creds usually printed on the device) and look at what other d
by telecuda 8y ago
After a host made a suspicious/creepy comment about our stay, I started logging into host routers (creds usually printed on the device) and look at what other devices are connected. The camera may not be on that network, or not networked at all, but it’s a little peace of mind.
- wil421 8y agoThere is an app called Fing on iPhones and maybe Android. It will scan the WiFi you are on and give you a bunch of information. There’s also a few more network functions you can do. It recognizes phones, my plex server, and a brother printer at my house to name a few. No router login required just the WiFi password.
- morpheuskafka 8y agoAnd using Fing (works better on Android b/c on iOS it can't access raw MAC addresses) is perfectly legal. The fact that a default password is used or the password is posted on the router is not in any way legal permission to access it as a short-term guest. Look at Aaron Swartz's case if you don't know how readily prosecutors will (ab)use the CFAA.
- rhinoceraptor 8y agoSomeone who didn't know to change their default Linksys password is probably not going to report the crime.
- paulie_a 8y agoHonestly who cares if it is illegal? What are they going to do? Literally nothing would ever happen. Using default creds on a home router really isn't going to get a prosecutors interest. They would probably laugh at you after you filed a complaint.
- AlexandrB 8y ago> There is an app called Fing on iPhones and maybe Android. This seemed like a really useful tool; I looked it up on the app store and - uh oh - it's free. Screenshots don't seem to show any ads and there's no IAP, so how do they make their money? Taking a look at their privacy policy[1], they collect: > Information on MAC addresses and Wi-Fi networks you collect through the App or the Box. Please note that this Privacy Policy does not exempt you from any obligations you may incur should you collect other individuals’ personal data. So basically, Fing will help you find devices on your network, and then store what it finds forever for other uses. And if you accidentally reveal some PII to Fing while scanning someone's network that's your problem. This is the state of "apps". Collect everything, store everything, disavow any responsibility for anything. One of the first phone apps I used was a G-meter that just read the accelerometer and showed you a graph of your acceleration. It was a neat little toy. Today that app would send all accelerometer data back to some server farm in case there's anything that can be mined from that data. [1] https://www.fing.io/fing-privacy-policy/ https://www.fing.io/fing-privacy-policy/
- dylan604 8y agoSo, download it while in the AirBnB. If it shares data permanently about the AirBnB location, fine. Delete the app immediately after using it. At your next AirBnB stay, do it all over again.
- AlexandrB 8y agoI don't actually use AirBnB very often. But I do end up doing network maintenance for friends, family and at the startup I work at. Fing seems like it would be useful for that purpose - but not with this kind of privacy policy. Also, just like it's not ok for hosts to put cameras in the properties they're renting out, I don't think it would be ok for me, as a guest, to knowingly upload data that I would consider sensitive to a third party. Treat others how you would want to be treated, right?
- tomaskafka 8y agoAs a host, I'd get a router with a separate guest network anyway. Fing wouldn't find anything.
- rhinoceraptor 8y agoarp-scan(1) can also do this without harvesting your data.
- andonisus 8y agoAt the risk of sounding condescending, what you did was a crime and potentially makes you liable under the CFAA. Probably, no one in law enforcement would care, but I would not advise doing this in the future.